cbcvebase.

Adobe Coldfusion vulnerabilities

240 known vulnerabilities affecting adobe/coldfusion.

Total CVEs
240
CISA KEV
17
actively exploited
Public exploits
23
Exploited in wild
27
Severity breakdown
CRITICAL76HIGH66MEDIUM89LOW9

Vulnerabilities

Page 3 of 12
CVE-2022-35712P2CRITICALCVSS 9.8v2018v2021+1 more2022-10-14
CVE-2022-35712 [CRITICAL] CWE-122 CVE-2022-35712: Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap- Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, the vulnerability is triggered when a crafted network packet is sent
nvd
CVE-2025-43562P2CRITICALCVSS 9.1v2021v2023+2 more2025-05-13
CVE-2025-43562 [CRITICAL] CWE-78 CVE-2025-43562: ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Neutralization ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security mechanis
nvd
CVE-2017-11283P2CRITICALCVSS 9.8v11.0v20162017-12-01
CVE-2017-11283 [CRITICAL] CWE-502 CVE-2017-11283: Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earl Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 and earlier versions for ColdFusion 11.
nvd
CVE-2017-11284P2CRITICALCVSS 9.8v11.0v20162017-12-01
CVE-2017-11284 [CRITICAL] CWE-502 CVE-2017-11284: Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earl Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 and earlier versions for ColdFusion 11.
nvd
CVE-2022-38421P2HIGHCVSS 7.2v2018v2021+1 more2022-10-14
CVE-2022-38421 [HIGH] CWE-22 CVE-2022-38421: Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Impr Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, but does require admi
nvd
CVE-2026-47928P2CRITICALCVSS 10.0v2023v2023-update1+28 more2026-06-09
CVE-2026-47928 [CRITICAL] CWE-20 CVE-2026-47928: ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnera ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
nvd
CVE-2019-7839P2CRITICALCVSS 9.8v11.0v2016+2 more2019-06-12
CVE-2019-7839 [CRITICAL] CWE-77 CVE-2019-7839: ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a co ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2026-27305P2HIGHCVSS 8.6v2023v2023-update1+25 more2026-04-14
CVE-2026-27305 [HIGH] CWE-22 CVE-2026-27305: ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issu
nvd
CVE-2026-48276P2CRITICALCVSS 10.0v2023v2023-update1+30 more2026-06-30
CVE-2026-48276 [CRITICAL] CWE-434 CVE-2026-48276: ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
nvd
CVE-2019-7091P2CRITICALCVSS 9.8v11.0v2016+2 more2019-05-24
CVE-2019-7091 [CRITICAL] CWE-502 CVE-2019-7091: ColdFusion versions Update 1 and earlier, Update 7 and earlier, and Update 15 and earlier have a des ColdFusion versions Update 1 and earlier, Update 7 and earlier, and Update 15 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2025-30281P2CRITICALCVSS 9.1v2021v2023+2 more2025-04-08
CVE-2025-30281 [CRITICAL] CWE-284 CVE-2025-30281: ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution. A high-privileged attacker could leverage this vulnerability to access or modify sensitive data without proper authorization. Exploitation of this issue does not require user interaction, a
nvd
CVE-2018-15957P2CRITICALCVSS 9.8v11.0v2016+2 more2018-09-25
CVE-2018-15957 [CRITICAL] CWE-502 CVE-2018-15957: Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2022-38419P2HIGHCVSS 7.5v2018v2021+1 more2022-10-14
CVE-2022-38419 [HIGH] CWE-611 CVE-2022-38419: Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Impr Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary file system read. Exploitation of this issue does not require user interaction.
nvd
CVE-2016-1114P2CRITICALCVSS 9.8v10.0v11.0+1 more2016-05-11
CVE-2016-1114 [CRITICAL] CWE-502 CVE-2016-1114: Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 allows remote att Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
nvd
CVE-2026-48277P2CRITICALCVSS 10.0v2023v2023-update1+30 more2026-06-30
CVE-2026-48277 [CRITICAL] CWE-20 CVE-2026-48277: ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnera ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
nvd
CVE-2026-48281P2CRITICALCVSS 10.0v2023v2023-update1+30 more2026-06-30
CVE-2026-48281 [CRITICAL] CWE-20 CVE-2026-48281: ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnera ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
nvd
CVE-2018-15959P2CRITICALCVSS 9.8v11.0v2016+2 more2018-09-25
CVE-2018-15959 [CRITICAL] CWE-502 CVE-2018-15959: Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2018-15965P2CRITICALCVSS 9.8v11.0v2016+2 more2018-09-25
CVE-2018-15965 [CRITICAL] CWE-502 CVE-2018-15965: Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2018-15958P2CRITICALCVSS 9.8v11.0v2016+2 more2018-09-25
CVE-2018-15958 [CRITICAL] CWE-502 CVE-2018-15958: Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2019-7840P2CRITICALCVSS 9.8v11.0v2016+2 more2019-06-12
CVE-2019-7840 [CRITICAL] CWE-502 CVE-2019-7840: ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a de ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
Adobe Coldfusion vulnerabilities | cvebase